CVE-2026-4213: D-Link DNS-1550-04 gui_mgr.cgi cgi_myfavorite_verify stack-based overflow
A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function cgimyfavoritedeluser/cgimyfavoriteverify of the file /cgi-bin/guimgr.cgi. Performing a manipulation results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4213?
CVE-2026-4213 is rated with high severity due to its potential for stack-based buffer overflow which can lead to remote code execution.
How do I fix CVE-2026-4213?
To fix CVE-2026-4213, update the affected D-Link devices to the latest firmware version released after February 5, 2026.
Which D-Link products are affected by CVE-2026-4213?
CVE-2026-4213 affects various D-Link models including DNS-120, DNS-320L, DNS-340L, among others.
What kind of attack can CVE-2026-4213 enable?
CVE-2026-4213 can enable attackers to execute arbitrary code on the affected devices through a crafted request.
Is there a workaround for CVE-2026-4213 if I cannot update?
As a temporary workaround for CVE-2026-4213, restrict WAN access to the devices and monitor the network for suspicious activity.